PT-2022-3529 · Secheron · Secheron Sepcos

Anthony Candarini

+3

·

Published

2022-05-10

·

Updated

2022-07-05

·

CVE-2022-1667

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Secheron SEPCOS Single Package relay control and protection software (affected versions not specified)
Description The issue is related to the incorrect implementation of a sequence of actions in the software. It allows a remote attacker to reboot the device by running a JS function or loading a corresponding PHP script. This can be achieved by directly running a JS function to reboot the PLC, for example, from the browser console, or by loading the browser-accessible PHP script.
Recommendations As a temporary workaround, consider disabling the JS function that allows rebooting the device until a patch is available. Restrict access to the PHP script that can reboot the device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04312
CVE-2022-1667

Affected Products

Secheron Sepcos